Back
Original version

On the Verge of Cyberwar: How M.E.Doc Monopolized the Accounting Reporting Market

Automatically translated version. May contain inaccuracies compared to the original.

On the Verge of Cyberwar: How M.E.Doc Monopolized the Accounting Reporting Market

Market experts believe the likelihood of a second wave of the virus is very high.

As a result of the cyberattack on 27 June, when the virus infected hundreds of thousands of computers across the country through the M.E.Doc accounting program, many companies are still dealing with the consequences. At the same time, there is a strong possibility that this attack was only reconnaissance and the real cyberwar is still ahead.

The development of the virus cost at least $300 thousand

Experts unanimously warn about the consequences of the next viral attack. Microsoft Ukraine’s CTO Mykhailo Shmelev said as early as 30 June that the infection occurred more than 200 days earlier and those who created this virus are unlikely to stop at just the first wave of attacks. The head of the parliamentary committee on informatization and communications, MP Oleksandr Danchenko, expressed the view that these are only the initial “childish” manifestations of the virus embedded in M.E.Doc updates and aimed specifically at the state of Ukraine. He believes that other countries received only the “splashes” of this viral assault. Expert estimates put the cost of developing and implementing such an attack from 300 thousand to several million dollars.

To date no one knows exactly which viruses were distributed through M.E.Doc software and how many of them are in a “sleep” mode waiting for their moment.

ESET experts (one of the most authoritative organizations for analyzing malware threats — ed.) in their detailed report of 4 July 2017 recorded the following conclusions: “As our analysis shows, this was a carefully planned and well-executed operation. We assume the attackers had access to the M.E.Doc application source code. They had time to study the code and include a very stealthy and clever backdoor.”

“Leaky” software

The key point of these conclusions is the assumption that such a backdoor (that is, a “back door,” which in programmer slang is called a “hole”) could only have been created by specialists who had access to the source code of M.E.Doc programs. In other words, the operation was deliberate and internal. This assumption should be a very alarming signal for all security services responsible for Ukraine’s cybersecurity. It is not only that information disappeared from the computers of hundreds of thousands of accountant-users. And not even that Boryspil airport, Nova Poshta and many banks were halted. It turns out that M.E.Doc (and the affiliated LLC Intellect-Service) control many critically important services within the State Fiscal Service itself.

First, the software for the Register of Tax Invoices is the work of these very “sweet” companies. The amount of abuse and theft through manipulation of the Register of Tax Invoices has caused the state multimillion losses, and “leaky” software is an ideal tool for such manipulations because it allows attackers to hide traces of interference.

Second, the software for receiving reporting documents from taxpayers, which specialists call the “gateway,” was developed by M.E.Doc. And, as practice shows, it is fully controlled by that company’s specialists. More precisely, by a single specialist. This is the only expert who has access to the gateway software and can change its operation at any second. He can also stop the resource’s operation, block all reporting operators except M.E.Doc itself, or make changes to the report processing procedures and notify no one about them, of course, except his own M.E.Doc program.

Three days of downtime

Such monopolization of access and control over the reporting-receipt software is very dangerous for the work of the SFS. For example, starting on 19 June, SFS report reception was completely stopped and did not resume for several days. Over three days, from 19 to 21 June, the situation in the SFS reached a “boiling point,” and accountants’ nerves were once again on edge. But no one within the SFS structure could determine the cause or fix the situation.

Apparently, the SFS has neither documentation, nor source code, nor intellectual property rights for the so-called “gateway.” Otherwise one cannot explain the fact that the gateway’s operation was restored only after a specialist from M.E.Doc arrived and fixed the malfunction in a few hours. Although the cause of the gateway software failure was never established.

One cannot fail to note the strange coincidence of the three-day gateway outage with another event — the suspension from duty of the head of the SFS IT department, Dmytro Lukianov. This information protection specialist, who previously worked at the National Bank, maintains long-standing ties with Serhiy Lynnyk — owner of LLC Intellect-Service.

Lukianov and Lynnyk repeatedly appeared together at various expert panels and visited state bodies — for example, to meetings with the chair of the Verkhovna Rada committee on tax and customs policy, Nina Yuzhanina. In those instances, Lynnyk always played the leading role, with Lukianov supporting him.

Monopoly in accounting reporting

The gateway stopping precisely when Dmytro Lukianov was suspended from his position but not dismissed from the SFS is a good reason to prove Lukianov’s value without exposing him to blame. After all, restoring the loyal Lukianov to the key position of head of the SFS IT department is the most reliable way to preserve Intellect-Service’s monopoly control of the gateway.

In fact, this incident with the three-day gateway stoppage showed: in the current operational scheme, Intellect-Service can dictate its rules to both the SFS and taxpayers. The monopoly right to manage the only reporting-receipt gateway provides broad opportunities to control the situation overall.

And if those behind embedding viruses into M.E.Doc software really have access to this product’s source code, the malicious potential of using such widespread software could be colossal.

In the first stage end-user programs were infected. In the second, attackers can target the software installed within the SFS itself.

Based on the above, the possibility of “prying open a crack” in software inside the SFS via the gateway software is the simplest two-step trick for an enemy intelligence service. Then hackers would enter SFS databases, then all databases connected to the SFS of central government bodies, and gain real levers of control over the situation — from data substitution to complete destruction.

How M.E.Doc squeezed out competitors

For this scenario, hackers and enemy intelligence services must obtain as much information as possible about the gateway’s structure and ways of interacting with it. Considering that M.E.Doc software, which includes the gateway inside the SFS, is built on archaic tools and the protection even of Intellect-Service’s own servers is absolutely leaky, this development is more than likely.

Another aspect to consider is the competitive struggle for the reporting market. Until now, M.E.Doc suppressed all competitors precisely by virtue of its monopolistic ability to influence the reporting-receipt gateway within the SFS. Any of the reporting operators (Sonata, I-Fin, E-doc and others) can provide numerous examples when their clients’ reports were delayed at the gateway level, while M.E.Doc clients’ reports were successfully and timely accepted by the gateway.

Six months ago the situation changed dramatically: amendments were made to the Tax Code that predetermined the emergence of the electronic taxpayer cabinet — a cloud service that could become a direct and free competitor to M.E.Doc.

“M.E.Doc” against creating the taxpayer cabinet

This became a significant threat to M.E.Doc. Therefore Intellect-Service is making every effort to prevent the creation of a modern taxpayer cabinet and to discredit everyone working on it inside and outside the SFS. In such a situation, spreading viruses from the SFS electronic cabinet is a very effective competitive tactic that could become the second wave of a viral attack. This scenario is quite likely, since the electronic taxpayer cabinet uses the same gateway that is fully controlled by Intellect-Service.

Therefore the situation requires urgent, highly qualified action by the security services and cyber police in cooperation with leading domestic and global cyber defense companies. Our state cannot be held hostage by the financial interests of a single company and the low qualifications of its developers who create insecure software.

Ultimately, this is a national security issue that should be considered at the level of the National Security Council.

kp.ua

Open the news PDF proof

Document: PDF proof of the original version of the news item "На пороге кибервойны: как M.E.Doc монополизировал рынок бухгалтерской отчетности". It records the publication content at the moment of the first scan, the preservation date and the source: ANTIKOR.

Document: PDF proof of the original version of the news item "На пороге кибервойны: как M.E.Doc монополизировал рынок бухгалтерской отчетности". It records the publication content at the moment of the first scan, the preservation date and the source: ANTIKOR.

На пороге кибервойны: как M.E.Doc монополизировал рынок бухгалтерской отчетности

По мнению экспертов рынка, вероятность второй волны вируса очень велика.

С последствиями кибератаки 27 июня, когда вирус проник в сотни тысяч компьютеров по всей стране через программу бухгалтерского учета M.E.Doc, многие компании разбираются до сих пор. Вместе с тем велика вероятность, что эта атака была только разведкой, а настоящая кибервойна впереди.

Разработка вируса стоила минимум $300 тысяч

Эксперты в один голос предупреждают о последствиях следующей вирусной атаки. Технический директор «Майкрософт-Украина» Михаил Шмелев еще 30 июня заявил, что инфицирование произошло более 200 дней назад и те, кто создавал данный вирус, вряд ли ограничатся только первой волной атаки. Глава профильного комитета по информатизации и связи ВР Украины, депутат Александр Данченко высказал мнение, что это — лишь первые «детские» проявления того вируса, заложенного в обновления «Медка» и направленного конкретно против государства Украины. В остальные же страны, по его мнению, долетели только «брызги» этой вирусного штурма. Экспертная оценка стоимости разработки и реализации такой атаки от 300 тысяч до нескольких миллионов долларов.

На сегодняшний день никто не знает, какие именно вирусы были распространены через программное обеспечение M.E.Doc и сколько из них находится в «спящем» режиме, ожидая своего часа.

Эксперты ESET (одной из самых авторитетных организаций по анализу угроз от вредоносных программ. — Авт.) в своем подробном отчете от 4 июля 2017 года зафиксировали следующие выводы: «Как показывает наш анализ, это тщательно спланированная и хорошо выполненная операция. Мы предполагаем, что злоумышленники имели доступ к исходному коду приложения M.E.Doc. У них было время изучить код и включить очень скрытный и хитрый бэкдор».

«Дырявое» программное обеспечение

Ключевый момент этих выводов — предположение о том, что такой бэкдор (то есть «задняя дверь», которая на сленге программистов называется «дыркой») могли сделать только специалисты, имеющие доступ к исходным текстам программ «Медка». То есть действовали не торопясь и изнутри. Данное предположение должно стать очень тревожным сигналом для всех спецслужб, которые отвечают за кибербезопасность Украины. Дело не только в том, что информация пропала у сотен тысяч пользователей-бухгалтеров. И даже не в том, что остановились аэропорт «Борисполь», «Новая почта» и множество банков. Оказывается, M.E.Doc (и аффилированный с ним ООО «Интеллект-сервис») контролируют многие принципиально важные сервисы внутри самого ГФС.

Во-первых, программное обеспечение для Реестра налоговых накладных — дело рук именно этих «сладких» компаний. Количество злоупотреблений и воровства за счет манипулирования с Реестром налоговых накладных нанесло государству многомиллионные убытки, и «дырявое» программное обеспечение является идеальным инструментом для таких манипуляций, поскольку позволяет скрыть следы вмешательства злоумышленников.

Во-вторых, программное обеспечение для приема отчетных документов от налогоплательщиков, которое специалисты называют «шлюз», разработано в компании M.E.Doc. И, как показывает практика, полностью контролируется специалистами этой компании. Точнее, одним специалистом .Это единственный эксперт, который имеет доступ к программному обеспечению шлюза приема отчетности и может изменить его работу в любую секунду. Он же может остановить работу ресурса, заблокировать работу всех операторов сдачи отчетности, кроме самого M.E.Doc, либо внести изменения в процессы обработки отчетности и не сообщить о них никому, естественно, кроме своей собственной программы M.E.Doc.

Три дня простоя

Такая монополизация доступа и управления работой программного обеспечения приема отчетности очень опасна для работы ДФС. Например, начиная с 19 июня, прием отчетности в ГФС полностью остановился и не запускался несколько дней. За три дня, с 19 по 21 июня, ситуация в ДФС дошла до «точки кипения», а нервы бухгалтеров в очередной раз были на пределе. Но никто в структуре ГФС не смог ни определить причину, ни исправить ситуацию.

По-видимому, ни документации, ни исходных текстов, ни авторских прав на так называемый «шлюз» у ГФС нет. Иначе нельзя объяснить тот факт, что работоспособность шлюза была восстановлена только после приезда специалиста из Медка, который за несколько часов устранил поломку. Хотя причина отказа программного обеспечения шлюза так и не была установлена.

Нельзя не отметить странное совпадение трехдневного простоя шлюза с еще одним событием — отстранением от занимаемой должности руководителя IT-департамента ДФС Дмитрия Лукьянова. Этот специалист по «защите информации», который ранее работал в Нацбанке, поддерживает давние связи с Сергеем Линником — владельцем ООО «Интеллект-Сервис».

Лукьянов и Линник неоднократно в паре выступали на различных экспертных столах и ходили в государственные органы — к примеру, на совещания к главе комитета Верховной Рады Украины по вопросам налоговой и таможенной политики ВР Нине Южаниной. При этом ведущую роль всегда играл Линник, а Лукьянов его поддерживал.

Монополия в бухгалтерской отчетности

Остановка работы шлюза как раз в тот момент, когда Дмитрий Лукьянов был отстранен от должности, но не уволен из ДФС, — хороший повод доказать ценность отстраненного Лукьянова, не подставляя его под удар. В конце концов, восстановление лояльного Лукьянова на ключевой должности руководителя IT-департамента ГФС — это самый надежный способ сохранения монопольного управления шлюзом со стороны «Интеллект-сервиса».

На самом деле этот инцидент с трехдневной остановкой шлюза показал: в существующей на сегодняшний день схеме работы «Интеллект-сервис» может диктовать свои правила и ГФС, и налогоплательщикам. Монопольное право управления единственным шлюзом приема отчетности дает широкие возможности управления ситуацией в целом.

И если те, кто стоит за внедрением вирусов в программное обеспечение M.E.Doc действительно имеют доступ к исходным текстам этого продукта, степень вредоносности от использования такого распространенного софта может быть колоссальной.

На первом этапе были заражены программы конечных пользователей. На втором — злоумышленники могут нацелиться на программное обеспечение, установленное в самой ГФС.

Исходя из вышесказанного, возможность «приоткрыть щелочку» в программном обеспечении внутри ГФС через программное обеспечение шлюза — простейшая двухходовка спецслужб врага. А потом хакеры войдут в базы данных ГФС, затем во все связанные с ДФС базы данных центральных органов власти и получат реальные рычаги управления ситуацией — от подмены данных до полного их уничтожения.

Как «Медок» давил конкурентов

Для этого сценария хакеры и спецслужбы врага должны получить максимум информации об устройстве шлюза и способах взаимодействия с ним. Учитывая тот факт, что программное обеспечение M.E.Doc, к которому относится и шлюз внутри ГФС, построены на допотопных инструментах, а защита даже собственных серверов «Интеллект-сервиса» абсолютно дырявая, такой вариант развития событий более, чем вероятен.

Необходимо учитывать еще один аспект, связанный с конкурентной борьбой за рынок сдачи отчетности. До сих пор «Медок» давил всех конкурентов именно за счет монопольной возможности влиять на шлюз приема отчетности внутри ГФС. Любой из операторов сдачи отчетности (Соната, I-Fin, Е-док и другие) могут привести огромное количество примеров, когда отчеты их клиентов тормозились на уровне шлюза, в то время, как отчеты клиентов «Медка» шлюзом успешно и вовремя принимались.

Полгода назад ситуация поменялась кардинальным образом: в Налоговый кодекс были внесены изменения, которые предопределили появление электронного кабинета налогоплательщика — облачного сервиса, который может стать прямым и бесплатным конкурентом «Медка».

«Медок» против создания кабинета налогоплательщика

Для «Медка» это стало существенной угрозой. Поэтому «Интеллект-сервис» прилагает массу усилий, чтобы не допустить создания современного кабинета налогоплательщика и дискредитировать всех тех, кто над ним работает в ГФС и за ее пределами. В такой ситуации распространение вирусов из электронного кабинета ГФС — это очень эффективный метод конкурентной борьбы, который может стать второй волной вирусной атаки. Этот вариант развития событий вполне вероятен, поскольку электронный кабинет налогоплательщика использует тот же шлюз, который полностью контролируется «Интеллект-сервисом».

Поэтому ситуация требует экстренных и высококвалифицированных действий со стороны спецслужб и киберполиции в кооперации с ведущими отечественными и мировыми компаниями в области киберзащиты. Наше государство не может быть заложником финансовых интересов одной компании и низкой квалификации ее разработчиков, создающих незащищенное программное обеспечение.

В конечном итоге, это вопрос национальной безопасности, который должен рассматриваться на уровне Совета Национальной безопасности.

kp.ua

Open the news PDF proof

Document: PDF proof of the original version of the news item "На пороге кибервойны: как M.E.Doc монополизировал рынок бухгалтерской отчетности". It records the publication content at the moment of the first scan, the preservation date and the source: ANTIKOR.

Document: PDF proof of the original version of the news item "На пороге кибервойны: как M.E.Doc монополизировал рынок бухгалтерской отчетности". It records the publication content at the moment of the first scan, the preservation date and the source: ANTIKOR.

Download Download PDF